Entra ID

Microsoft Entra ID Security Updates: Key 2026 Changes

2 min read

Summary

Microsoft is making three important Microsoft Entra ID security changes in 2026: retiring Custom controls in favor of External MFA, enforcing Conditional Access more consistently during credential registration, and requiring explicitly registered authentication methods for SSPR. These updates matter because they close policy enforcement gaps, improve identity security, and require admins to review configurations before enforcement deadlines arrive.

Need help with Entra ID?Talk to an Expert

Introduction

Microsoft is tightening Microsoft Entra ID security in several areas that directly affect authentication, Conditional Access, and self-service password reset. For IT admins, these changes are important because they remove legacy behavior, close enforcement gaps, and require preparation ahead of hard deadlines in 2026.

What’s new in Microsoft Entra ID

1. Custom controls are being deprecated

Microsoft is retiring Custom controls and steering organizations to External MFA for third-party MFA integrations in Conditional Access.

  • Existing Custom controls will keep working during the transition period
  • Retirement date: September 30, 2026
  • End of life: May 2027
  • External MFA offers deeper integration and a more modern, standards-based approach

If your organization still relies on Custom controls, migration planning should start now.

2. Conditional Access will apply consistently during credential registration

Starting the week of July 6, 2026, Conditional Access policies targeting the Register security information action will also apply to:

  • Windows Hello for Business provisioning
  • macOS Platform Single Sign-on registration

This closes a long-standing gap where some registration experiences were not governed by the same Conditional Access rules used elsewhere. Users who do not meet policy requirements may see additional prompts during setup or registration.

3. SSPR will require registered authentication methods

Microsoft is changing self-service password reset (SSPR) so only explicitly registered authentication methods can be used.

  • Registration campaign starts: July 6, 2026
  • Enforcement begins: September 7, 2026
  • Directory-based phone numbers or email addresses that were never formally registered will no longer work for SSPR verification

This aligns password reset with stronger proof-of-possession and user-verified authentication methods.

Impact on IT administrators

These changes could affect onboarding, device setup, password reset success rates, and third-party MFA integrations. Organizations that do not prepare may see user friction, help desk volume increases, or unsupported legacy configurations as enforcement dates approach.

What admins should do now

  • Inventory any Custom controls dependencies
  • Review External MFA migration requirements
  • Test registration-related Conditional Access policies in report-only mode
  • Validate Windows Hello for Business and macOS registration scenarios
  • Audit SSPR readiness and identify users relying on unregistered directory values
  • Communicate upcoming registration prompts and deadlines to users and support teams

The main takeaway: review your Entra ID authentication and access policies now so these 2026 security changes do not disrupt users later.

Need help with Entra ID?

Our experts can help you implement and optimize your Microsoft solutions.

Talk to an Expert

Stay updated on Microsoft technologies

Entra IDConditional AccessExternal MFASSPRidentity security

Related Posts

Entra ID

Microsoft Entra Passkeys for External IdP App Sign-Ins

Microsoft has made browser-based authentication for external identity providers generally available for supported Microsoft app sign-ins on Android, iOS, and managed macOS. This lets federated Microsoft 365 users use passkeys, FIDO2 security keys, and eligible SSO sessions in apps like Outlook, Teams, and OneDrive, reducing password fallback and embedded web view limitations.

Entra ID

Microsoft Entra Tenant Governance Webinars 2026

Microsoft is promoting upcoming webinars focused on securing multi-tenant environments with Microsoft Entra Tenant Governance, now generally available. The sessions highlight how organizations can detect shadow tenants, apply consistent governance, and build a stronger identity foundation for AI readiness.

Entra ID

Microsoft Entra App Gallery Self-Service Onboarding Preview

Microsoft has launched a public preview of self-service onboarding for new Microsoft Entra App Gallery applications. The new workflow lets publishers validate OIDC, SAML, and provisioning integrations before submission, then create, submit, and track app listings in the Entra admin center, reducing delays and rework.

Entra ID

Microsoft Entra Private Access Replaces VPNs

Microsoft is positioning Entra Private Access as a practical replacement for traditional VPNs, using identity-driven, per-app access instead of broad network tunnels. The guidance outlines a phased migration approach that helps IT teams reduce attack surface, strengthen Zero Trust controls, and simplify remote access operations.

Entra ID

HiBob Microsoft Entra Integration Now Generally Available

Microsoft has announced general availability of HiBob’s native integration with Microsoft Entra, enabling HR-driven identity lifecycle automation for joiners, movers, and leavers. The integration helps IT teams govern provisioning and access changes across hybrid and cloud environments while reducing manual processes and security risk.

Entra ID

Microsoft Entra September 2026: Key Identity Updates

Microsoft Entra's September 2026 updates introduce new tenant governance, user-centric access reviews, lifecycle workflow cloning, and passwordless resource accounts for Teams devices. The release also adds cloud-to-AD provisioning, AI-focused MCP Firewall protections, and important deadlines for MemberOf-based configurations and permission scope changes.